CVE-2020-26978: Medium severity thunderbird vulnerability
Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-26978?
CVE-2020-26978 is classified as a high severity vulnerability that could lead to information disclosure.
How do I fix CVE-2020-26978?
To mitigate CVE-2020-26978, users should upgrade to Firefox version 84 or later, or to the latest versions of Firefox ESR or Thunderbird.
What types of software are affected by CVE-2020-26978?
CVE-2020-26978 affects Mozilla Firefox versions before 84, Firefox ESR versions before 78.6, and Thunderbird versions before 78.6.
Can CVE-2020-26978 be exploited remotely?
Yes, CVE-2020-26978 can be exploited via a malicious webpage that users visit.
What kind of data could be exposed due to CVE-2020-26978?
CVE-2020-26978 could expose internal network hosts and services running on the user's local machine.